CVE-2018-7910: Medium severity huawei alp-al00b-rsc firmware vulnerability
Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8.0.0.137(C432), BLA-L29C 8.0.0.129(C432), 8.0.0.137(C432) have an authentication bypass vulnerability. When the attacker obtains the user's smartphone, the vulnerability can be used to replace the start-up program so that the attacker can obtain the information in the smartphone and achieve the purpose of controlling the smartphone.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7910?
The severity of CVE-2018-7910 is medium with a score of 6.8.
Which Huawei smartphones are affected by CVE-2018-7910?
The Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8.0.0.137(C432), BLA-L29C 8.0.0.129(C432), 8.0.0.137(C432) are affected by CVE-2018-7910.
What is the vulnerability in Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128(C432), 8.0.0.137(C432), BLA-L29C 8.0.0.129(C432), 8.0.0.137(C432)?
The vulnerability in these Huawei smartphones is an authentication bypass vulnerability.
How can an attacker exploit CVE-2018-7910?
An attacker can exploit CVE-2018-7910 by obtaining the user's smartphone and bypassing the authentication.
Is there a fix available for CVE-2018-7910?
Yes, Huawei has provided a security advisory with information on how to fix CVE-2018-7910. Please refer to the reference link for more details.